Логотип exploitDog
bind:CVE-2025-67721
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-67721

Количество 2

Количество 2

nvd логотип

CVE-2025-67721

около 2 месяцев назад

Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed input. With certain crafted compressed inputs, elements from the output buffer can end up in the uncompressed output, potentially leaking sensitive data. This is relevant for applications that reuse the same output buffer to uncompress multiple inputs. This can be the case of a web server that allocates a fix-sized buffer for performance purposes. There is similar vulnerability in GHSA-cmp6-m4wj-q63q. This issue is fixed in version 3.4.

EPSS: Низкий
github логотип

GHSA-vx9q-rhv9-3jvg

около 2 месяцев назад

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-67721

Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed input. With certain crafted compressed inputs, elements from the output buffer can end up in the uncompressed output, potentially leaking sensitive data. This is relevant for applications that reuse the same output buffer to uncompress multiple inputs. This can be the case of a web server that allocates a fix-sized buffer for performance purposes. There is similar vulnerability in GHSA-cmp6-m4wj-q63q. This issue is fixed in version 3.4.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vx9q-rhv9-3jvg

aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу